How to clean malware from a hacked WordPress site
If your site shows spam pages, redirects visitors, or Google flags it, it may be infected. Act quickly and calmly.
- Take the site offline or into maintenance mode to protect visitors.
- Change all passwords — WordPress admin, hosting, FTP and database.
- Scan with a security plugin such as Wordfence or MalCare and let it remove infected files.
- Update WordPress core, all themes and plugins, and delete any you do not recognise or use.
- Restore a clean backup from before the infection if you have one — our DirhamVault off-site backups keep dated copies.
After cleaning, install a firewall, enable 2FA, and request a review in Google Search Console to clear any warning. Malware usually gets in through outdated plugins or weak passwords, so keeping everything updated prevents a repeat.
Our UAE-based team is available 24/7 and can help investigate and restore your site. Contact WhatsApp +971 58 553 6767 or support@dirhamaday.ae straight away if you suspect a hack.
Still need a hand? Our UAE-based team is here 24/7.